CVE-2026-40465
An Open Re-direct Vulnerability in Nokia NSP
Public disclosure |
31-08-2026 |
|---|---|
Last updated |
31-08-2026 |
Vulnerability type |
URL Redirection to Untrusted Site ('Open Redirect') |
CVSS vector |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N |
CVSS score |
5.3 |
Description
NSP is vulnerable to an open redirect due to insufficient server-side validation of the URL (or redirect) parameter.
Affected products and versions
NSP versions 23.11, 24.4, 24.8, 24.11, 25.4, 25.8 and 25.11.
Mitigation plan
Fixes have been provided in NSP 24.11-SP15, NSP 25.11-SP5, NSP 26.4 and later releases.